Hacker101 CTF
The Hacker101 CTF is a game designed to let you learn to hack in a safe, rewarding environment. Hacker101 is a free educational site for hackers.
Awesome Vulnerable Applications
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
The Hacker101 CTF is a game designed to let you learn to hack in a safe, rewarding environment. Hacker101 is a free educational site for hackers.
PortSwigger - A set of materials and labs to learn and exploit common web vulnerabilities.
An online platform to test and advance your skills in penetration testing and cyber security. Join today and start training in our online labs.
TryHackMe is an online platform that teaches cyber security through short, gamified real-world labs.
Directory of upcoming and archive of past Capture The Flag (CTF) competitions with links to challenge writeups.
is a non-commercial wargame site which provides various pwn challenges regarding system exploitation.
A game about tricking people into running code in their browsers.
Pentest-Tools.com - Pentest-Ground is a free playground with deliberately vulnerable web applications and network services.
Damn Vulnerable AI Bank
PentesterLab - Hands on labs to understand and exploit simple and advanced web vulnerabilities.
Pre-Built Vulnerable Environments Based on Docker-Compose
Variety of VMs to learn variety of computer security issues.
Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.
Kubernetes Goat is "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security.
CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository.
Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository.
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository.
Repository demonstrating the Capital One breach on your AWS account
WrongSecrets is "Vulnerable by Design" to show how to not handle secrets in Docker, Kubernetes and in the cloud (AWS/GCP/Azure).
A Damn Vulnerable AWS Infrastructure
A Damn Vulnerable Azure Infrastructure
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure
CNAPPgoat is a multi-cloud, vulnerable-by-design environment deployment tool.
An insecure cloud-native microservices demo application for Kubernetes
Intentionally vulnerable GCP and AWS infrastructure deployed with Terraform for authorized cloud security training.
vulnerable single sign on
Allsafe is an intentionally vulnerable application that contains various vulnerabilities.
Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities.
A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation.
A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
Damn Vulnerable Bank is designed to be an intentionally vulnerable android application.
An Intentionally designed Vulnerable Android Application built in Kotlin.
AndroGoat is purposely developed open source vulnerable/insecure app using Kotlin.
Damn Insecure and vulnerable App for Android.
Damn Vulnerable Mobile App, an intentionally vulnerable Flutter app for Android and iOS.
Oversecured Vulnerable Android App.
Android Application covering various static and dynamic vulnerabilities.
hpAndro1337 Application made in Kotlin with multiple vulnerabilities and a CTF.
Intentionally vulnerable Android app covering OWASP Mobile Top 10 classes with exploit commands and screenshots.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
completely ridiculous API: crAPI will help you to understand the ten most critical API security risks. crAPI is vulnerable by design, but you'll be able to safely run it to educate/train yourself.
Damn Vulnerable Web Application (DVWA)
Damn Small Vulnerable Web
This is just an instance of the OWASP bWAPP project as a docker container.
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
This web application is a demonstration of common server-side application flaws. Each of the vulnerabilities has its own difficulty rating.
OWASP Mutillidae II is a free, open source, deliberately vulnerable web-application providing a target for web-security enthusiast.
Local penetration testing lab using docker-compose.
A vulnerable web application lab using Docker
WebGoat is a deliberately insecure application by OWASP for training purpose
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing
An intentionally vulnerable e-commerce application built with Next.js and React. A self-hosted CTF platform for web security training covering OWASP Top 10 vulnerabilities.
A modular deliberately vulnerable application designed primarily for validating and benchmarking security scanners through reproducible test scenarios, while also supporting learning and experimentation.
Yet Another Vulnerability Database
Docker container that intakes post and then "clicks" the link. Intentionally vulnerable. To be used with vulnerable by design web apps to realistically simulate XSS and XSRF (CSRF).
Self-replication contest
A set of XSS vulnerable PHP scripts for testing
A vulnerable blogging platform used to demonstrate XSS vulnerabilities.
This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack
Sample vulnerable code and its exploit code
This Repository contains CORS misconfiguration related vulnerable codes.
A simple web app with a XXE vulnerability.
Docker image to test XXE attacks in java with tomcat.
This repository a docker-compose file to setup a local environment that is vulnerable to CVE-2021-36740 Varnish HTTP/2 request smuggling.
Damn Vulnerable WordPress
Interactive educational project that demonstrates common security vulnerabilities in .NET applications
A step by step workshop to exploit various vulnerabilities in Node.js and Java applications
Damn Vulnerable NodeJS Application
Extreme Vulnerable Node Application
Damn Vulnerable Web Service is a vulnerable web service/API/application that can be used to learn webservices/API vulnerabilities.
The Damn Vulnerable Router Firmware Project
IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.
Damn Vulnerable IoT Device
A playground for testing, preventing, and logging IDOR vulnerabilities.
Deliberately Vulnerable GitHub Actions CI/CD Environment
Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities.
A vulnerable C program for testing fuzzers.
The Web Application Vulnerability Scanner Evaluation Project
Benchmarking repo for secrets scanning
Repo for all the OWASP-SKF Docker lab examples
Vulnerable server used for learning software exploitation
Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.
An intentionally vulnerable NGINX setup
The intentionally vulnerable image for the Raspberry Pi.
This repository collects lists of security-relavent Python APIs, along with examples of exploits using those APIs
The OWASP Vulnerable Web Applications Directory project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
Pre-Built Vulnerable Environments Based on Docker-Compose
Web app for hunters
Deliberately vulnerable CI/CD environment. Hack CI/CD pipelines, catch the flags.
Damn Vulnerable Thick Client App developed in C# .NET
Intentionally vulnerable Web API game for learning and training purposes dedicated to developers, ethical hackers and security engineers.
.NET vulnerable REST API
Vulnerable Web application made with PHP/SQL designed to help new web testers gain some experience and test DAST tools for identifying web vulnerabilities.
Intentionally vulnerable AI agent lab for practicing RAG injection, tool misuse, memory poisoning, supply-chain compromise, and data exfiltration.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.